CVE-2026-58107: Authenticated Remote Denial of Service via Unbounded zlib Decompression in massStoreRun
CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size.
An authenticated user with permission to store analysis runs can submit a highly compressed payload that expands to a significantly larger byte sequence. Because the entire decompressed output is materialized in memory before being written to a temporary file, a sufficiently large payload may exhaust process or host memory and consume substantial disk space, resulting in denial of service.
Affected Software
Event History
Frequently Asked Questions
Does any authenticated CodeChecker user have the required access to trigger this issue?
No. The user must be authenticated and have permission to store analysis runs.
What resources can be exhausted by a malicious submission?
The decompressed data is fully materialized in memory before it is written to a temporary file. A sufficiently large expansion can consume process or host memory and substantial disk space.